CVE-2019-20869: Medium severity mattermost vulnerability
Published Jun 19, 2020
·Updated
An issue was discovered in Mattermost Server before 5.10.0, 5.9.1, 5.8.2, and 4.10.9. A non-member could change the Update/Patch Channel endpoint for a private channel.
Affected Software
10 affected components
Mattermost Mattermost Server<4.10.9
Mattermost Mattermost Server>=5.7.0<5.7.3
Mattermost Mattermost Server>=5.8.0<5.8.2
Mattermost Mattermost Server>=5.9.0<5.9.1
Mattermost Mattermost Server=5.10.0-rc1
Mattermost Mattermost Server=5.10.0-rc2
Mattermost Mattermost Server=5.10.0-rc3
Mattermost Mattermost Server=5.10.0-rc4
Mattermost Mattermost Server=5.10.0-rc5
Mattermost Mattermost Server=5.10.0-rc6
Event History
Jun 19, 2020
CVE Published
via MITRE·03:21 PM
Data Sourced
via MITRE·03:21 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-20869?
CVE-2019-20869 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2019-20869?
To fix CVE-2019-20869, upgrade Mattermost Server to version 5.10.0 or later.
3
Who is affected by CVE-2019-20869?
CVE-2019-20869 affects Mattermost Server versions before 5.10.0, 5.9.1, 5.8.2, and 4.10.9.
4
What does CVE-2019-20869 exploit?
CVE-2019-20869 allows a non-member to change the Update/Patch Channel endpoint for a private channel.
5
Is there a workaround for CVE-2019-20869?
There is no formal workaround for CVE-2019-20869, upgrading to a patched version is recommended.